2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-13085 | CRITICAL | 9.8 | 0.5% | Dec 31, 2024 | A vulnerability, which was classified as critical, has been found in PHPGurukul Land Record System 1.0. Affected by this... |
| CVE-2024-13084 | CRITICAL | 9.8 | 0.4% | Dec 31, 2024 | A vulnerability classified as critical was found in PHPGurukul Land Record System 1.0. Affected by this vulnerability is... |
| CVE-2024-56198 | CRITICAL | 9.3 | 0.7% | Dec 31, 2024 | path-sanitizer is a simple lightweight npm package for sanitizing paths to prevent Path Traversal. Prior to 3.1.0, the f... |
| CVE-2024-13072 | CRITICAL | 9.8 | 0.6% | Dec 31, 2024 | A vulnerability was found in 1000 Projects Beauty Parlour Management System 1.0. It has been rated as critical. Affected... |
| CVE-2024-56066 | CRITICAL | 9.8 | 0.6% | Dec 31, 2024 | Missing Authorization vulnerability in inspry Agency Toolkit agency-toolkit allows Privilege Escalation.This issue affec... |
| CVE-2024-56045 | CRITICAL | 9.3 | 0.7% | Dec 31, 2024 | Path Traversal: '.../...//' vulnerability in VibeThemes WPLMS wplms_plugin allows Path Traversal.This issue affects WPLM... |
| CVE-2024-56044 | CRITICAL | 9.8 | 0.8% | Dec 31, 2024 | Authentication Bypass Using an Alternate Path or Channel vulnerability in VibeThemes WPLMS wplms_plugin allows Authentic... |
| CVE-2024-56043 | CRITICAL | 9.8 | 0.6% | Dec 31, 2024 | Incorrect Privilege Assignment vulnerability in VibeThemes WPLMS wplms_plugin allows Privilege Escalation.This issue aff... |
| CVE-2024-56040 | CRITICAL | 9.8 | 0.7% | Dec 31, 2024 | Incorrect Privilege Assignment vulnerability in VibeThemes VibeBP vibebp allows Privilege Escalation.This issue affects ... |
| CVE-2024-56205 | CRITICAL | 9.8 | 0.6% | Dec 31, 2024 | Incorrect Privilege Assignment vulnerability in SunnyKai AI Magic newsletter-page-redirects allows Privilege Escalation.... |
| CVE-2024-56071 | CRITICAL | 9.8 | 0.6% | Dec 31, 2024 | Incorrect Privilege Assignment vulnerability in mikeleembruggen Simple Dashboard simple-dashboard allows Privilege Escal... |
| CVE-2024-56064 | CRITICAL | 10 | 14.5% | Dec 31, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in azzaroco WP SuperBackup indeed-wp-superbackup allows Up... |
| CVE-2024-56046 | CRITICAL | 9.8 | 0.7% | Dec 31, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in VibeThemes WPLMS wplms_plugin allows Upload a Web Shell... |
| CVE-2024-56042 | CRITICAL | 9.8 | 0.7% | Dec 31, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VibeThemes WPLMS w... |
| CVE-2024-56039 | CRITICAL | 9.3 | 0.6% | Dec 31, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VibeThemes VibeBP ... |
| CVE-2024-13061 | CRITICAL | 9.8 | 1.2% | Dec 31, 2024 | The Electronic Official Document Management System from 2100 Technology has an Authentication Bypass vulnerability. Alth... |
| CVE-2024-12108 | CRITICAL | 9.6 | 6.8% | Dec 31, 2024 | In WhatsUp Gold versions released before 2024.0.2, an attacker can gain access to the WhatsUp Gold server via the public... |
| CVE-2024-56220 | CRITICAL | 9.8 | 0.4% | Dec 31, 2024 | Incorrect Privilege Assignment vulnerability in sslplugins SSL Wireless SMS Notification ssl-wireless-sms-notification a... |
| CVE-2024-11972 | CRITICAL | 9.8 | 54.8% | Dec 31, 2024 | The Hunk Companion WordPress plugin before 1.9.0 does not correctly authorize some REST API endpoints, allowing unauthen... |
| CVE-2024-56801 | CRITICAL | 9.8 | 0.7% | Dec 30, 2024 | Tasklists provides plugin tasklists for GLPI. Versions prior to 2.0.4 have a blind SQL injection vulnerability. Version ... |
| CVE-2024-56799 | CRITICAL | 10 | 0.5% | Dec 30, 2024 | Simofa is a tool to help automate static website building and deployment. Prior to version 0.2.7, due to a design mistak... |
| CVE-2024-10044 | CRITICAL | 9.3 | 0.5% | Dec 30, 2024 | A Server-Side Request Forgery (SSRF) vulnerability exists in the POST /worker_generate_stream API endpoint of the Contro... |
| CVE-2024-47926 | CRITICAL | 9.8 | 0.5% | Dec 30, 2024 | Tecnick TCExam – CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') |
| CVE-2024-47919 | CRITICAL | 9.8 | 1.5% | Dec 30, 2024 | Tiki Wiki CMS – CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') |
| CVE-2024-22063 | CRITICAL | 9 | 0.8% | Dec 30, 2024 | The ZENIC ONE R58 products by ZTE Corporation have a command injection vulnerability. An authenticated attacker can expl... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now